End-To-End Secure Cloud Computing
Claim Score by NHIP
Abstract
A method includes receiving, at a control node of a cloud computing network, a first enterprise policy specific to the first enterprise and a second enterprise policy specific to the second enterprise, and managing communications between at least one user device of the first enterprise and the at least one enterprise application hosted on behalf of the first enterprise based on the first enterprise policy. The method also includes managing communications between at least one user device of the second enterprise and the at least one enterprise application hosted on behalf of the second enterprise based on the second enterprise policy.

Term
5.1 yearsto projected expiry
Projected expiry 4 November 2031, counted from filing; an application has no term until it is granted.
- Priority and filed
- Published
- Today
- Projected expiry
20 claims: 3 independent, 17 dependent
- 1In a cloud computing network hosting at least one enterprise application on behalf of a first enterprise and hosting at least one enterprise application on behalf of a second enterprise, a method comprising:receiving, at a control node of the cloud computing network, a first enterprise policy specific to the first enterprise and a second enterprise policy specific to the second enterprise, the first enterprise policy representing security and access policies for the first enterprise and the second enterprise policy representing security and access policies for the second enterprise;managing, at the control node, communications between at least one user device of the first enterprise and the at least one enterprise application hosted on behalf of the first enterprise based on the first enterprise policy;and managing, at the control node, communications between at least one user device of the second enterprise and the at least one enterprise application hosted on behalf of the second enterprise based on the second enterprise policy.
- 8Broadest claimClaim Score 68, broad(NHIP)A method comprising:configuring a first set of user devices for use by a first enterprise to interface with at least one enterprise application hosted at a cloud computing network on behalf of the first enterprise, the cloud computing network managed by a service provider;determining a first enterprise policy representing access and security policies specific to the first enterprise;and providing the first enterprise policy to the service provider for use in managing communications between the first set of user devices and the at least one enterprise application hosted at the cloud computing network.
- 14A cloud computing network managed by a service provider, the cloud computing network comprising:at least one data center to host enterprise applications on behalf of a plurality of enterprises;a policy database to store data representative of enterprise policies for the plurality of enterprises, each enterprise policy representing access and security policies specific to a corresponding enterprise;and a control node to manage communications between at least one user device of an enterprise and at least one enterprise application hosted at the at least one data center on behalf of the enterprise based on the corresponding enterprise policy.
Independent claims3
42 paragraphs in 4 sections, as filed
FIELD OF THE DISCLOSURE
p-0002The present disclosure relates generally to networking and relates more particularly to cloud computing.
BACKGROUND
p-0003Cloud computing increasingly is implemented as an alternative to conventional client-server computing environments. In cloud computing, hardware and software resources are supplied to remote computing devices on-demand. In a conventional cloud computing environment, the resources of the “cloud” are shared among multiple users. This approach typically provides reduced costs and oversight on a per-user basis as each user is no longer required to acquire, configure, and manage a separate computing infrastructure.
BRIEF DESCRIPTION OF THE DRAWINGS
p-0004It will be appreciated that for simplicity and clarity of illustration, elements illustrated in the Figures have not necessarily been drawn to scale. For example, the dimensions of some of the elements are exaggerated relative to other elements. Embodiments incorporating teachings of the present disclosure are shown and described with respect to the drawings presented herein, in which:
p-0005<figref idrefs="DRAWINGS">FIG. 1</figref> is a diagram illustrating a networked system employing secure end-to-end cloud computing for a plurality of enterprises in accordance with at least one embodiment of the present disclosure;
p-0006<figref idrefs="DRAWINGS">FIG. 2</figref> is a flow diagram illustrating a method for utilizing enterprise-specific access and security policies at a cloud computing network of the networked system of <figref idrefs="DRAWINGS">FIG. 1</figref>, in accordance with at least one embodiment of the present disclosure;
p-0007<figref idrefs="DRAWINGS">FIG. 3</figref> is a block diagram illustrating functional components of a virtual private gateway (VPG) device of the networked system of <figref idrefs="DRAWINGS">FIG. 1</figref> in accordance with at least one embodiment of the present disclosure; and
p-0008<figref idrefs="DRAWINGS">FIG. 4</figref> is a diagram illustrating an example computer system for implementing one or more of the components or techniques described herein in accordance with at least one embodiment of the present disclosure.
p-0009The use of the same reference symbols in different drawings indicates similar or identical items.
DETAILED DESCRIPTION OF THE DRAWINGS
p-0010The numerous innovative teachings of the present application will be described with particular reference to the presently preferred example embodiments. However, it should be understood that this class of embodiments provides only a few examples of the many advantageous uses of the innovative teachings herein. In general, statements made in the specification of the present application do not necessarily delimit any of the various claimed inventions. Moreover, some statements may apply to some inventive features but not to others.
p-0011<figref idrefs="DRAWINGS">FIGS. 1-4</figref> illustrate techniques for providing end-to-end secure cloud computing in a networked system. In at least one embodiment, a service provider manages or otherwise provides a cloud computing network including or having access to one or more servers, data storage components, and other resources. Software applications employed by an enterprise, referred to herein as “enterprise applications,” are hosted at the cloud computing network. The enterprise accordingly employs thin client devices or other user devices configured to provide graphical user interfaces (GUIs) to facilitate users' interactions with the executed enterprise applications, such as by receiving user input via keyboards, mice, and touch screens, and by displaying graphical representations of information provided by the executed enterprise applications. To provide improved security and simplified management, the network access and security policies of an enterprise are implemented at the cloud computing network rather than within the local computing infrastructure of the enterprise. Accordingly, the enterprise determines an enterprise policy to be employed by the cloud computing network specifically with respect to communications between the enterprise applications hosted in the cloud computing network and the corresponding end-point devices associated with the enterprise. The enterprise provides this enterprise policy to the service provider, which then implements the enterprise policy within the cloud computing network so as to manage communications between the end-point devices and the hosted enterprise applications.
p-0012By migrating both the applications of an enterprise and responsibility for implementing the access and security policies of the enterprise to the cloud computing network, the enterprise can achieve the desired computing services in a more cost-effective, secure, and simplified manner. For one, fully-functional, stand-alone endpoint user devices, such as conventional notebook computers and desktop computers, are expensive to acquire and to maintain. The techniques described herein enable an enterprise to replace these more costly fully-functional user devices with less costly and simpler thin client devices that typically provide resources sufficient only to enable the capture and transmission of user input to a remote application and the display of graphics information from the remote application. The replacement of fully-functional user devices with thin client devices also enhances security. The thin client devices can be configured so as to prevent the persistent storage of potentially confidential data, thereby mitigating the risk of data loss or data theft. Moreover, the thin client devices can be configured so as to only support the thin client application, thereby circumventing users' attempts to use unauthorized software at the user device or to use authorized software in an unauthorized manner, as well as mitigating the risk of infection by a virus or other malware.
p-0013An enterprise utilizing a conventional client-server system typically is required to employ complex local area network (LAN) routing, LAN security, and demilitarized zone (DMZ) security to connect and protect enterprise assets, as well as providing extensive data center security to protect physical access to enterprise data and assets. In contrast, the implementation of enterprise policies at the cloud computing network instead of within the enterprise infrastructure itself enhances security and simplifies management by shifting management of the enterprise-specified security and access policies, physical access control, and infrastructure configuration, maintenance, and management to a third-party service provider managing the cloud computing network.
p-0014<figref idrefs="DRAWINGS">FIG. 1</figref> illustrates a networked system <b>100</b> employing end-to-end secure cloud computing in accordance with at least one embodiment of the present disclosure. The system <b>100</b> includes a cloud computing network <b>102</b> managed by a third-party service provider. The cloud computing network <b>102</b> includes a shared computing infrastructure, such as one or more data centers, such as data centers <b>104</b>, <b>105</b>, and <b>106</b>. The cloud computing network <b>102</b> further includes a secure network control node <b>108</b> and one or more security services nodes <b>110</b> that are coupled to the data centers via one or more secure networks <b>112</b> internal to the cloud computing network <b>102</b>. Examples of the secure network <b>112</b> can include an internet protocol multimedia subsystem (IMS)-based network or a multiprotocol label switching (MPLS)-based network.
p-0015The data centers <b>104</b>-<b>106</b> each includes computing resources that facilitate the hosting of enterprise data and enterprise applications in the cloud computing network <b>102</b> on behalf of one or more enterprises. These resources include data storage components, such as disk drives or nonvolatile memory, to store the enterprise applications and the data. These resources further include server computers to execute the enterprise applications and to access and store data to the data storage components accordingly. In one embodiment, the resources of the data centers are virtually shared computing resources, such as those shared on-demand between multiple enterprises. In this instance, the data centers can implement server virtualization whereby a server computer may be simultaneously shared between multiple enterprises using the appropriate virtualization masking protocols to prevent access between applications executed by one enterprise and applications executed by another enterprise on the same server. Alternatively, certain enterprises may have a service level agreement (SLA) or other arrangement with the service provider whereby certain resources of one or more of the data centers <b>104</b>-<b>106</b> are dedicated solely for use by the corresponding enterprise.
p-0016The secure network control node <b>108</b>, in one embodiment, manages communications between end-point devices of the enterprises and the computing resources of the cloud computing network <b>102</b> that support the enterprises. As such, the secure network control node <b>108</b> operates as the gateway interface between external enterprise user devices and the data centers <b>104</b>-<b>106</b>. Further, the cloud computing network <b>102</b> may make use of resources in a public network <b>114</b> in supporting one or more enterprises. To illustrate, the cloud computing network <b>102</b> may interface with various Internet-based servers, such as web server <b>116</b> or content server <b>118</b>, which execute enterprise applications or otherwise provide, store, or manipulate data on behalf of the enterprises. In these instances, the secure network control node <b>108</b> also operates as the gateway interface between external enterprise user devices and the public network <b>114</b>.
p-0017The secure network control node <b>108</b> facilitates simplification and cost-reduction in managing enterprise computing resources by employing the network access and security policies of an enterprise (hereinafter, the “enterprise policy”) within the cloud computing network <b>102</b>, rather than within the local infrastructure of the corresponding enterprise. To this end, the secure network control node <b>108</b> includes a virtual private gateway (VPG) device <b>120</b> and a policy database <b>122</b> or other data storage component. The policy database <b>122</b> stores data representative of the enterprise policies of the enterprises supported by cloud computing network <b>102</b> and the VPG device <b>120</b> manages ingress and egress communications between the enterprise end-point devices, the data centers <b>104</b>-<b>106</b>, and the one or more public networks <b>114</b> in accordance with the access and security policies outlined in the stored enterprise policies. As different enterprises have different access control and security needs, the secure network control node <b>108</b> employs separate enterprise policies for the supported enterprises, each enterprise policy specific to the corresponding enterprise and configured in accordance with the specifications and parameters supplied by the enterprise.
p-0018As described in greater detail below with reference to <figref idrefs="DRAWINGS">FIG. 3</figref>, the VPG device <b>120</b> provides various functionality for securing communications through traffic encryption/decryption and virtual private network (VPN) techniques, for access control/authentication of enterprise users/user devices, for packet-filtering and application-level filtering, network address translation, traffic routing, and the like. Certain of these functions may be implemented, in whole or in part, through the use of the one or more security services nodes <b>110</b> configured accordingly by the VPG device <b>120</b>. To illustrate, the cloud computing network <b>102</b> may provide hypertext transfer protocol (HTTP) proxying for an enterprise's access of internet resources, and the security services node <b>110</b> may configure or manage the appropriate security settings for the proxy server employed for the proxying.
p-0019By implementing an enterprise's access and security policies within the shared infrastructure of the cloud computing network <b>102</b>, the enterprise is no longer required to acquire and maintain a relatively expensive and complex computing, networking, and security infrastructure. The computing infrastructure is replaced by equivalent shared infrastructure in the cloud computing environment. The enterprise's networking infrastructure thus can be simplified because its functionality is now reduced to routing traffic between the cloud computing infrastructure and the end devices. The security infrastructure likewise is simplified because it is largely implemented within the shared infrastructure of the cloud computing network rather than on the enterprise's premises.
p-0020Fully-functional stand-alone user devices, which otherwise would be necessary to implement an enterprise's computing infrastructure, instead can be replaced with relatively inexpensive and simple thin client devices with an operating system or platform kernel of limited functionality, such as one that is intended solely to support the capture and transmission of user input to a remote location and the corresponding display of graphical information from the remote location. As a data loss prevention measure, one or more of the thin client devices of an enterprise can be configured so as to prevent continued storage of data associated with an enterprise application beyond the corresponding period of interaction between the thin client device and the enterprise application. Further, as a security measure, one or more of the thin client devices of an enterprise can be configured so as to prevent the installation and execution of non-authorized software, thereby mitigating the risk of unauthorized access to enterprise data or applications through malicious software executed at a user device.
p-0021<figref idrefs="DRAWINGS">FIG. 1</figref> depicts three examples of enterprises supported by shared computing resources of the cloud computing network <b>102</b>. In the first example scenario, an enterprise <b>130</b> employs user devices <b>131</b> and <b>132</b> and a wireless access point <b>134</b>. The wireless access point <b>134</b> is connected to the cloud computing network <b>102</b> via a network connection <b>136</b>. The network connection can include, for example, a digital subscriber line (DSL) connection, a satellite connection, a mobile data connection, and the like. In this example, the user devices <b>131</b> and <b>132</b> are virtual workstations employed as thin client devices configured with a remote desktop protocol (RDP) agent so as to establish, via the secure network control node <b>108</b>, a remote desktop session with one or more enterprise applications hosted by the cloud computing network <b>102</b>.
p-0022In the second example scenario, an enterprise <b>140</b> employs user devices <b>141</b> and <b>142</b> and a wired local area network (LAN) <b>144</b>. The LAN <b>144</b> in turn is connected to the cloud computing network <b>102</b> via a network connection <b>146</b>. The user devices <b>141</b> can include, for example, a thin client device and a fully-functional notebook computer, respectively, each employing a Citrix XenApp™ client application that establishes a remote desktop services (RDS) session with one or more enterprise applications hosted by the cloud computing network <b>102</b> on behalf of the enterprise <b>140</b>.
p-0023In the third example scenario, an enterprise <b>150</b> employs mobile devices <b>151</b> and <b>152</b>, which can include, for example, computing-enabled cellular phones, networked personal digital assistants, networked tablet computers, and the like. The mobile user devices <b>151</b> and <b>152</b> are connected to the cloud computing network <b>102</b> via a base station transceiver (BTS) <b>154</b> and a mobile telecommunications link <b>156</b>. The mobile devices <b>151</b> and <b>152</b> can employ any of a variety of means of establishing connections with one or more enterprise applications executed at the cloud computing network <b>102</b> on behalf of the enterprise <b>150</b>. To illustrate, the mobile devices <b>151</b> and <b>152</b> can execute an RDP-based client application to establish an RDS session with an executed enterprise application. Alternatively, the mobile devices <b>151</b> and <b>152</b> can employ a web browser or other user interface or local application to access data and processing functionality provided by the cloud computing network <b>102</b> on behalf of the enterprise <b>150</b>.
p-0024The enterprise <b>150</b> further can include a user device <b>153</b>, such as a thin client device, tethered to the mobile device <b>151</b> via, for example, a wired connection (such as a Universal Serial Bus connection) or a short-range wireless connection (such as a Bluetooth wireless connection). In this configuration, the mobile device <b>151</b> is configured to act as a wireless modem or other conduit for communications to and from the user device <b>153</b> and thus the user device <b>153</b> uses the connectivity of the mobile device <b>151</b> to interact with one or more enterprise applications hosted by the cloud computing network <b>102</b> on behalf of the enterprise <b>150</b>.
p-0025The enterprise policy to be implemented by the secure network control node <b>108</b> for an enterprise may depend on the user devices associated with the enterprise. To illustrate, the policies for fixed endpoints typically are different than mobile endpoints. It often is not practicable to implement a virtual private network (VPN) agent at mobile devices such as mobile phones, and thus communications between the mobile device and the Internet often are not protected from snooping. However, as illustrated by the third example scenario, the thin client device <b>153</b> can establish a secured connection with the cloud computing network <b>102</b> using a VPN or an encryption technique, and the mobile device <b>151</b> can be configured merely as the conduit for communications between the thin client device <b>153</b> and the cloud computing network <b>102</b>.
p-0026<figref idrefs="DRAWINGS">FIG. 2</figref> illustrates an example method <b>200</b> for providing secure, efficient, and cost-effective cloud computing services to an enterprise via implementation of the policies of the enterprise at the cloud computing network rather than within the enterprise's local infrastructure. For ease of discussion, the method <b>200</b> is described in the context of the networked system <b>100</b> of <figref idrefs="DRAWINGS">FIG. 1</figref>. Further, <figref idrefs="DRAWINGS">FIG. 2</figref> illustrates the depicted blocks in a certain order for descriptive purposes and this order is not necessarily indicative of an order in which the processes represented by the depicted blocks are performed.
p-0027At block <b>202</b>, an enterprise identifies one or more enterprise applications to be hosted by the cloud computing network <b>102</b>. The enterprise further identifies enterprise data to be stored at the cloud computing network <b>102</b>. The enterprise coordinates the installation or migration of the identified enterprise applications and enterprise data to one or more of the data centers <b>104</b>-<b>106</b> of the cloud computing network <b>102</b>.
p-0028At block <b>204</b>, the enterprise identifies the enterprise policy representing the enterprise's intended access and security policies with respect to access to, and operation of, the enterprise applications and enterprise data identified at block <b>202</b>. The enterprise policy can include, for example, security services information. The security services information can identify protocols and other configuration information for authenticating or authorizing a user or user device, limits on access to certain data or certain enterprise applications (or certain functions of certain enterprise) by a user or user devices, limits on access to uniform resource locators (URLs) or other public network destinations reachable by a user or user device, packet filtering criteria, email filtering criteria, and distributed denial of service (DDoS) detection and prevention criteria. The enterprise policy further can include, for example, enterprise-specific network address translation (NAT), enterprise-specific traffic rerouting or proxying, traffic encryption/decryption, and the like.
p-0029At block <b>206</b>, the enterprise supplies information or data representative of the determined enterprise policy to the service provider managing or otherwise responsible for the cloud computing network <b>102</b>. This information or data can be input into the policy database <b>122</b> directly by an operators associated with the enterprise via, for example, a GUI provided by the secure network control node <b>108</b>. Alternatively, the operator can submit this information to the service provider, and another operator associated with the service provider then may enter the policy information in the appropriate format into the policy database <b>122</b>.
p-0030At block <b>208</b>, the enterprise provides user devices and configures the user devices to communicate with the cloud computing network <b>102</b> for operation of, or interaction with, the enterprise applications hosted at the cloud computing network <b>102</b> and for access to enterprise data stored at the cloud computing network <b>102</b>. This configuration process can include installation of a RDP client or other thin client agent at the user device. As another example, the configuration process can include configuring proxy information for a web browser or other GUI application implemented at the user device.
p-0031Turning to the operations of the cloud computing network <b>102</b>, at block <b>210</b> the service provider allocates resources of the cloud computing network <b>102</b> for hosting the enterprise applications and for storing the enterprise data identified at block <b>202</b>. The identification and allocation of resources may be made subject to a service level agreement or other arrangement between the service provider and the enterprise. As noted above, the cloud computing network <b>102</b> may provide resources in an on-demand basis, and thus the cloud computing network <b>102</b> may dynamically allocate resources for hosting enterprise applications based on the current requirements of the user devices of the enterprise.
p-0032As part of the hosting process, the VPG device <b>108</b> and one or more security services nodes <b>110</b> of the cloud computing network <b>102</b> manage communications between the user devices of the enterprise and the hosted enterprise applications based on the enterprise policy determined at block <b>204</b>. The management of these communications can include, for example, enterprise-specific security services, such as packet filtering, email filtering, application-level filtering, URL or port filtering, network address translation, and the like. The management of the communications further can include higher-level access and security functions, such as user/device authentication, identification-based access level control, DDoS detection and mitigation, traffic rerouting, traffic encryption/decryption, and the like.
p-0033In at least one embodiment, the service provider utilizes the cloud computing network <b>102</b> to host enterprise applications and enterprise data for a plurality of enterprises. In such instances, the processes of blocks <b>202</b>, <b>204</b>, <b>206</b>, <b>208</b>, <b>210</b>, and <b>212</b> can be separately performed for each enterprise and utilizing access and security policies specific to the parameters specified by the enterprise.
p-0034<figref idrefs="DRAWINGS">FIG. 3</figref> depicts a functional block diagram that illustrates an implementation of the VPG device <b>120</b> of <figref idrefs="DRAWINGS">FIG. 1</figref> in accordance with at least one embodiment. The VPG device <b>120</b> comprises a cryptographic functions module <b>310</b>, a policy functions module <b>320</b>, a routing functions module <b>330</b>, and a NAT functions module <b>340</b>. The cryptographic functions module <b>310</b> is operable to provide an interface between the security techniques and parameters associated with corresponding user devices and the security techniques and parameters associated with secured networks of the cloud computing network <b>102</b>. For example, the cryptographic functions module <b>310</b> may effectively translate between an encryption system used by a RDP client of a user device and an encryption system used by an internal secure network. The policy functions module <b>320</b> is operable to apply one or more of the access policies or security policies of the corresponding enterprise policy to the communication traffic received from, or provided to, user devices. The traffic policies may be associated with an internal secure network and the VPG device <b>120</b> may relieve the secure network of the need to enforce such policies. The routing functions module <b>330</b> is operable to route traffic in and out of a core network of the cloud computing network <b>102</b> in accordance with the specified enterprise policy. In one embodiment, the routing functions module <b>330</b> is configured to determine if communication traffic from the user devices is destined for a system/network outside of the secure network, such as the Internet at large. In this case, the routing functions module <b>130</b> may route such traffic to its final destination without passing through the secure network in accordance with the enterprise policy, thus relieving the secure network of the processing burden of redirecting the traffic to its intended destination. The NAT functions module <b>340</b> is operable to modify address information in packet headers in accordance with the enterprise policy so as to be able to remap from one address space to another. Further details regarding the VPG device <b>120</b> are found in co-pending U.S. patent application Ser. No. 12/610,746 entitled “Methods, Systems, and Computer Program Products for Providing a Virtual Private Gateway Between User Devices and Various Networks,” the entirety of which hereby is incorporated by reference.
p-0035<figref idrefs="DRAWINGS">FIG. 4</figref> shows an illustrative embodiment of a general computer system <b>400</b> in accordance with at least one embodiment of the present disclosure. The computer system <b>400</b> can include a set of instructions that can be executed to cause the computer system <b>400</b> to perform any one or more of the methods or computer-based functions disclosed herein. To illustrate, the computer system <b>400</b> can represent an implementation of a user device associated with an enterprise, an implementation of the secure network control node <b>108</b>, an implementation of the VPG device <b>120</b>, or a server computer of one of the data centers <b>104</b>-<b>106</b>. While a single computer system <b>400</b> is illustrated, the term “system” shall also be taken to include any collection of systems or sub-systems that individually or jointly execute a set, or multiple sets, of instructions to perform one or more computer functions.
p-0036The computer system <b>400</b> may include a processor <b>402</b>, such as a central processing unit (CPU), a graphics processing unit (GPU), or both. Moreover, the computer system <b>400</b> can include a main memory <b>404</b> and a static memory <b>406</b> that can communicate with each other via a bus <b>408</b>. As shown, the computer system <b>400</b> may further include a video display unit <b>410</b>, such as a liquid crystal display (LCD), an organic light emitting diode (OLED), a flat panel display, a solid state display, or a cathode ray tube (CRT). Additionally, the computer system <b>400</b> may include an input device <b>412</b>, such as a keyboard, and a cursor control device <b>414</b>, such as a mouse, joystick, or arrow pads. The computer system <b>400</b> can also include a disk drive unit <b>416</b>, a signal generation device <b>418</b>, such as a speaker or remote control, and a network interface device <b>420</b>.
p-0037In a particular embodiment, as depicted in <figref idrefs="DRAWINGS">FIG. 4</figref>, the disk drive unit <b>416</b> may include a computer-readable medium <b>422</b> in which one or more sets of instructions <b>424</b>, such as software, can be embedded. Further, the instructions <b>424</b> may embody one or more of the methods or logic as described herein. In a particular embodiment, the instructions <b>424</b> may reside completely, or at least partially, within the main memory <b>404</b>, the static memory <b>406</b>, and/or within the processor <b>402</b> during execution by the computer system <b>400</b>. The main memory <b>404</b> and the processor <b>402</b> also may include computer-readable media. The network interface device <b>420</b> can provide connectivity to a network <b>426</b>, such as a wide area network (WAN), a local area network (LAN), or other network.
p-0038In an alternative embodiment, dedicated hardware implementations such as application specific integrated circuits, programmable logic arrays and other hardware devices can be constructed to implement one or more of the methods described herein. Applications that may include the apparatus and systems of various embodiments can broadly include a variety of electronic and computer systems. One or more embodiments described herein may implement functions using two or more specific interconnected hardware modules or devices with related control and data signals that can be communicated between and through the modules, or as portions of an application-specific integrated circuit. Accordingly, the present system encompasses software, firmware, and hardware implementations.
p-0039In accordance with various embodiments of the present disclosure, the methods described herein may be implemented by software programs executable by a computer system. Accordingly, the present disclosure contemplates a computer-readable medium that includes instructions to perform one or more of the operations described above. In a particular non-limiting, exemplary embodiment, the computer-readable medium can include a solid-state memory such as a memory card or other package that houses one or more non-volatile read-only memories. Further, the computer-readable medium can be a random access memory or other volatile re-writeable memory. Additionally, the computer-readable medium can include a magneto-optical or optical medium, such as a disk or tapes or other storage device. Accordingly, the disclosure is considered to include any one or more of a computer-readable medium or a distribution medium and other equivalents and successor media, in which data or instructions may be stored.
p-0040Although the present specification describes components and functions that may be implemented in particular embodiments with reference to particular standards and protocols, the invention is not limited to such standards and protocols. For example, standards for Internet and other packet switched network transmission are periodically superseded by faster or more efficient equivalents having essentially the same functions. Accordingly, replacement standards and protocols having the same or similar functions as those disclosed herein are considered equivalents thereof.
p-0041The illustrations of the embodiments described herein are intended to provide a general understanding of the structure of the various embodiments. The illustrations are not intended to serve as a complete description of all of the elements and features of apparatus and systems that utilize the structures or methods described herein. Many other embodiments may be apparent to those of skill in the art upon reviewing the disclosure. Other embodiments may be utilized and derived from the disclosure, such that structural and logical substitutions and changes may be made without departing from the scope of the disclosure. Additionally, the illustrations are merely representational and may not be drawn to scale. Certain proportions within the illustrations may be exaggerated, while other proportions may be minimized. Accordingly, the disclosure and the figures are to be regarded as illustrative rather than restrictive.
p-0042The Abstract of the Disclosure is provided to comply with 37 C.F.R. §1.72(b) and is submitted with the understanding that it will not be used to interpret or limit the scope or meaning of the claims. In addition, in the foregoing Detailed Description of the Drawings, various features may be grouped together or described in a single embodiment for the purpose of streamlining the disclosure. This disclosure is not to be interpreted as reflecting an intention that the claimed embodiments require more features than are expressly recited in each claim. Rather, as the following claims reflect, inventive subject matter may be directed to less than all of the features of any of the disclosed embodiments. Thus, the following claims are incorporated into the Detailed Description of the Drawings, with each claim standing on its own as defining separately claimed subject matter.
p-0043The above disclosed subject matter is to be considered illustrative, and not restrictive, and the appended claims are intended to cover all such modifications, enhancements, and other embodiments which fall within the true spirit and scope of the present disclosed subject matter. Thus, to the maximum extent allowed by law, the scope of the present disclosed subject matter is to be determined by the broadest permissible interpretation of the following claims and their equivalents, and shall not be restricted or limited by the foregoing detailed description.
Contents4
5 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US2016028834A1 | Cited by | United States of America | Pre-grant |
| US2015071053A1 | Cited by | United States of America | Pre-grant |
| US9396339B2 | Cited by | United States of America | Search report |
| US11310108B2 | Cited by | United States of America | Applicant |
| US10049646B2 | Cited by | United States of America | Applicant |
| US8646064B1 | Cited by | United States of America | Applicant |
| US9516061B2 | Cited by | United States of America | Search report |
| US2013219483A1 | Cited by | United States of America | Pre-grant |
| US9167501B2 | Cited by | United States of America | Applicant |
| US10797962B2 | Cited by | United States of America | Applicant |
| US10075471B2 | Cited by | United States of America | Applicant |
| US9215264B1 | Cited by | United States of America | Search report |
| US9497661B2 | Cited by | United States of America | Search report |
| CN103795764A | Cited by | China | Search report |
| CN106375436A | Cited by | China | Search report |
| US10785099B2 | Cited by | United States of America | Applicant |
| US10055594B2 | Cited by | United States of America | Applicant |
| US9584482B2 | Cited by | United States of America | Applicant |
| US11469970B2 | Cited by | United States of America | Applicant |
| US11741963B2 | Cited by | United States of America | Applicant |
| US10129296B2 | Cited by | United States of America | Applicant |
| US2012151551A1 | Cited by | United States of America | Pre-grant |
| US2016170915A1 | Cited by | United States of America | Search report |
| US10402585B2 | Cited by | United States of America | Search report |
| US8416709B1 | Cited by | United States of America | Applicant |
| US10511624B2 | Cited by | United States of America | Applicant |
| US11909820B2 | Cited by | United States of America | Applicant |
| EP2629557A1 | Cited by | European Patent Office (EPO) | Search report |
| US12136425B2 | Cited by | United States of America | Applicant |
| US2014101317A1 | Cited by | United States of America | Pre-grant |
| US8613089B1 | Cited by | United States of America | Applicant |
| US12035070B2 | Cited by | United States of America | Applicant |
| US10171475B2 | Cited by | United States of America | Applicant |
| US8867361B2 | Cited by | United States of America | Search report |
| US10742805B2 | Cited by | United States of America | Applicant |
| US8776212B2 | Cited by | United States of America | Search report |
| US2018361236A1 | Cited by | United States of America | Search report |
| US10320635B2 | Cited by | United States of America | Applicant |
| US11539900B2 | Cited by | United States of America | Applicant |
| US9439243B2 | Cited by | United States of America | Search report |
| US10153943B2 | Cited by | United States of America | Search report |
| US10917519B2 | Cited by | United States of America | Applicant |
| US9288214B2 | Cited by | United States of America | Search report |
| US10440060B2 | Cited by | United States of America | Applicant |
| US2015309970A1 | Cited by | United States of America | Pre-grant |
| US12137183B2 | Cited by | United States of America | Applicant |
| US9160693B2 | Cited by | United States of America | Applicant |
| US2015249642A1 | Cited by | United States of America | Pre-grant |
| US10581904B2 | Cited by | United States of America | Applicant |
| US10389876B2 | Cited by | United States of America | Applicant |
| US8762501B2 | Cited by | United States of America | Applicant |
| US11290349B2 | Cited by | United States of America | Applicant |
| US2013110748A1 | Cited by | United States of America | Pre-grant |
| US8856295B2 | Cited by | United States of America | Search report |
| US2019012212A1 | Cited by | United States of America | Search report |
| US10748523B2 | Cited by | United States of America | Applicant |
| US2016191627A1 | Cited by | United States of America | Pre-grant |
| US2016087835A1 | Cited by | United States of America | Pre-grant |
| US9049235B2 | Cited by | United States of America | Applicant |
| US10726126B2 | Cited by | United States of America | Search report |
| US11750455B2 | Cited by | United States of America | Applicant |
| US2014032755A1 | Cited by | United States of America | Pre-grant |
| US10476765B2 | Cited by | United States of America | Applicant |
| US9906578B2 | Cited by | United States of America | Search report |
| US9705889B2 | Cited by | United States of America | Applicant |
| US2013133057A1 | Cited by | United States of America | Pre-grant |
| US9774634B2 | Cited by | United States of America | Applicant |
| US12452235B2 | Cited by | United States of America | Applicant |
| US2019012212A1 | Cited by | United States of America | Search report |
| EP2629557A1 | Cited by | European Patent Office (EPO) | Search report |
| US8856300B2 | Cited by | United States of America | Search report |
| US11991216B1 | Cited by | United States of America | Search report |
| US11290446B2 | Cited by | United States of America | Search report |
| US12432054B2 | Cited by | United States of America | Applicant |
| US9015809B2 | Cited by | United States of America | Applicant |
| WO2014014848A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US12289308B2 | Cited by | United States of America | Search report |
| US10057294B2 | Cited by | United States of America | Applicant |
| US9060025B2 | Cited by | United States of America | Search report |
| US9854443B2 | Cited by | United States of America | Applicant |
| US12400660B2 | Cited by | United States of America | Applicant |
| US2013179876A1 | Cited by | United States of America | Pre-grant |
| US9825992B2 | Cited by | United States of America | Applicant |
| US11212177B2 | Cited by | United States of America | Search report |
| US2013179874A1 | Cited by | United States of America | Pre-grant |
| EP3127035A4 | Cited by | European Patent Office (EPO) | Search report |
| US11327811B2 | Cited by | United States of America | Search report |
| US10217444B2 | Cited by | United States of America | Applicant |
| US2012259964A1 | Cited by | United States of America | Pre-grant |
| US2016170915A1 | Cited by | United States of America | Pre-grant |
| US11627221B2 | Cited by | United States of America | Applicant |
| US10326801B2 | Cited by | United States of America | Applicant |
| US11818167B2 | Cited by | United States of America | Applicant |
| US2014189797A1 | Cited by | United States of America | Pre-grant |
| US9641549B2 | Cited by | United States of America | Applicant |
| US10542141B2 | Cited by | United States of America | Applicant |
| US12445483B2 | Cited by | United States of America | Applicant |
| US11013994B2 | Cited by | United States of America | Search report |
| US2018361236A1 | Cited by | United States of America | Search report |
| US11323479B2 | Cited by | United States of America | Applicant |
8 members in 1 office; this record represents the family
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 78257810 | United States of America | A | |
| US20100782578 | – | – | – |
Members8
| Document | Office | Kind | |
|---|---|---|---|
| US2011289134A1 | United States of America | A1 | |
| US8856300B2 | United States of America | B2 | |
| US2016099971A1 | United States of America | A1 | |
| US9392023B2 | United States of America | B2 | |
| US2016261637A1 | United States of America | A1 | |
| US9774634B2 | United States of America | B2 | |
| US2018013797A1 | United States of America | A1 | |
| US10440060B2 | United States of America | B2 |
58 transactions on the USPTO file
Allowed after 2 non-final rejections, 1 final rejection and 1 RCE.
- Non-final rejections
- 2
- Final rejections
- 1
- RCEs
- 1
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Payment of Maintenance Fee, 12th Year, Large EntityM1553 | M1553 | |
| Payment of Maintenance Fee, 8th Year, Large EntityM1552 | M1552 | |
| Email NotificationEML_NTR | EML_NTR | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| Correspondence Address ChangeC.AD | C.AD | |
| Payment of Maintenance Fee, 4th Year, Large EntityM1551 | M1551 | |
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Patent Issue Date Used in PTA CalculationAllowedPTAC | PTAC | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Dispatch to FDCD1935 | D1935 | |
| Application Is Considered Ready for IssuePILS | PILS | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Issue Fee Payment ReceivedIFEE | IFEE | |
| Mail Notice of AllowanceAllowedMN/=. | MN/=. | |
| Notice of Allowance Data Verification CompletedAllowedN/=. | N/=. | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Reasons for AllowanceEX.R | EX.R | |
| Examiner's Amendment CommunicationEX.A | EX.A | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Mail Interview Summary - Applicant Initiated - TelephonicMEXAT | MEXAT | |
| Interview Summary- Applicant InitiatedEXIA | EXIA | |
| Interview Summary - Applicant Initiated - TelephonicEXAT | EXAT | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Correspondence Address ChangeC.ADB | C.ADB | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Disposal for a RCE / CPA / R129AbandonedABN9 | ABN9 | |
| Request for Continued Examination (RCE)RCEX | RCEX | |
| Workflow - Request for RCE - BeginBRCE | BRCE | |
| Mail Notice of Restarted Response PeriodMNRES | MNRES | |
| Letter Restarting Period for Response (i.e. Letter re References)NRES | NRES | |
| Interview Summary- Applicant InitiatedEXIA | EXIA | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Interview Summary - Examiner InitiatedEXIE | EXIE | |
| PG-Pub Issue NotificationPG-ISSUE | PG-ISSUE | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Application Dispatched from OIPEOIPE | OIPE | |
| Application Is Now CompleteCOMP | COMP | |
| Filing Receipt - UpdatedFLRCPT.U | FLRCPT.U | |
| Sent to Classification ContractorPGPC | PGPC | |
| Additional Application Filing FeesADDFLFEE | ADDFLFEE | |
| A statement by one or more inventors satisfying the requirement under 35 USC 115, Oath of the ApplicOATHDECL | OATHDECL | |
| Filing ReceiptFLRCPT.O | FLRCPT.O | |
| Notice Mailed--Application Incomplete--Filing Date AssignedINCD | INCD | |
| Cleared by OIPE CSRL194 | L194 | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| IFW Scan & PACR Auto Security ReviewSCAN | SCAN | |
| Initial Exam Team nnIEXX | IEXX |
9 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Maintenance fee paymentMAFP | MAFP | |
| AssignmentAS | AS | |
| Maintenance fee paymentMAFP | MAFP | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| Maintenance fee paymentMAFP | MAFP | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| Fee payment procedurePAYOR NUMBER ASSIGNED (ORIGINAL EVENT CODE: ASPN); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP | |
| AssignmentAS | AS |
Numbers
- Publication
- 20110289134
- Publication, DOCDB
- 2011289134
- Publication, EPODOC
- US2011289134
- Application
- 12782578
- Application, DOCDB
- 78257810
- Application, EPODOC
- US20100782578
Titles
- English
- End-To-End Secure Cloud Computing
Patent term adjustment
- A delay
- +535 daysthe office missed an examination deadline
- Net adjustment
- 535 days
Classification
- CPC, 10
- H04L63/20
- H04L47/70
- H04L63/08
- H04L63/205
- H04L63/04
- H04L63/10
- H04L67/01
- H04L41/5003
- H04L63/105
- H04L67/10
- IPC, 3
- G06F15 16
- G06F15 173
- G06F21 00
- USPC, 3
- 709203000
- 709223000
- 726001000